Product · Secure Edge
Secure Edge: Stop Threats at the Ingress, Before Origin
DDoS scrubbing, Next-Gen WAF, bot protection, TLS encryption and access control all run at the edge ingress. Three modes: Observation, Intercept, and Intercept + Ban — escalate from logging to hard blocking on your terms. Origin stays hidden.- L3-L7 DDoS scrubbing
- Next-Gen WAF
- Observation / Intercept / Ban
- Bot protection
Secure Edge
Security runs at the edge ingress
DDoS protection
L3/L4 volumetric and protocol attacks plus L7 application attacks scrubbed at the edge. Attack traffic is not billed.
Next-Gen WAF
OWASP Top 10 ruleset, adjustable paranoia level 1-4. Three modes: Observation (log only), Intercept (block malicious requests), Intercept + Ban (block and ban source IP). Hit logs available.
TLS & HTTPS
Free SSL certificates, TLS 1.3 + 0-RTT, forced HTTPS, TLS version control and origin validation.
Bot protection
Behavioral analysis detects scraping, credential stuffing and automated abuse to protect login, payment and API endpoints.
Secure Token
Signed tokens control media and resource access — hotlink and unauthorized distribution protection.
Access control
IP / region allow-deny lists, ACLs, CORS and rate limiting for fine-grained access management.
Why it matters
Traditional CDN security vs IXCDN Secure Edge
Traditional CDN
Security sold as a paid add-on, rules configured separately, suspicious traffic detected only after reaching origin.
IXCDN
DDoS / WAF / TLS / Token / access control enforced at one edge ingress. Observation → Intercept → Ban, escalate on demand. Origin hidden.
IXCDN